Industrial cybersecurity ยท Switzerland

Design compliant
machines.
Operate resilient industrial systems.

Soterio supports machine manufacturers in achieving compliance with EU Machinery Regulation 2023/1230, and industrial SMEs in securing their OT/ICS environments โ€” through a pragmatic, proportionate and directly actionable approach.

Discuss your situation โ†’
Regulatory deadline: 20 January 2027
Core offering

Compliance with
EU Machinery Regulation
2023/1230

EU Machinery Regulation 2023/1230 introduces new requirements related to protecting machinery against accidental or malicious corruption, particularly where this could compromise safety or the operation of control systems. These obligations will apply to machinery placed on the European Union market from 20 January 2027.

This is not a generic cybersecurity audit, but compliance-oriented support: identifying the machines and functions concerned, assessing gaps against the applicable requirements, and defining a realistic and proportionate remediation plan aligned with your risks, architectures and industrial constraints.

Annex III โ€” Art. 1.1.9

Protection against accidental or malicious corruption: integrity of critical hardware and software components, identification of interventions, and retention of the evidence needed to verify modifications.

Annex III โ€” Art. 1.2.1

Safety and reliability of control systems: resistance to external influences and unauthorised intervention, so that they cannot lead to a hazardous situation.

Process

Scope definition

Identification of in-scope machines and risk interfaces (HMI, maintenance ports, removable media).

Gap analysis

Comparison of the current state against the requirements of Articles 1.1.9 and 1.2.1 of Annex III.

Remediation plan

Prioritisation of actions based on risk level and technical and timeline constraints.

Compliance documentation

Formalisation of the analysis, identified gaps, selected measures and supporting evidence to be included in the technical documentation.

"Our machines are not connected to the Internet โ€” the regulation doesn't apply to us."

FALSE!

An offline machine is not an isolated machine.
  • USB media used for updates or file transfers
  • HMI interfaces or configuration functions with insufficient protection
  • Maintenance ports accessible to external equipment
  • Untracked parameter or software changes
  • Firmware or software loaded without integrity checks
  • Temporary connection to a customer or service provider network
Additional offering

Secure your operations
without disrupting production

Soterio supports industrial SMEs in identifying and reducing OT risks, with recommendations adapted to availability, maintenance and production continuity constraints.

[01]

Asset visibility

Inventory of connected industrial equipment (PLCs, HMI, SCADA), with identification of data flows and entry points.

[02]

Network segmentation

IT/OT environment separation, critical zone isolation, proportionate architecture recommendations.

[03]

Risk prioritisation

Identification of scenarios that could affect safety, availability or production, followed by a realistic treatment plan based on criticality.

Frequently asked questions

What I'm often
asked

Does the regulation apply if we only sell in Switzerland?

EU Machinery Regulation 2023/1230 applies to machinery placed on the European Union market. A Swiss company is therefore concerned as soon as it exports machinery to the EU, directly or through a distributor or customer.

Our machines are not connected. Are we affected?

Internet connectivity is not the only factor to consider. Removable media, local interfaces, maintenance ports and temporary connections can act as vectors for corruption or unauthorised intervention. Their relevance must be assessed as part of the machine risk analysis.

How is this different from a standard cybersecurity audit?

The engagement starts from the requirements applicable to the product and their impact on machine safety. The objective is to identify gaps, define the necessary measures and document the choices made. It is neither a generic penetration test nor an ISO certification.

Where should we start with less than a year before the deadline?

Start with a rapid scope assessment: relevant product ranges, critical functions, exposed interfaces and existing documentation. This first step makes it possible to identify priorities and build a realistic roadmap before launching the most demanding technical work.

Our team has no cybersecurity specialist. Is this suitable?

Yes. The engagement is designed to work with product, automation, R&D and compliance teams, even without dedicated cybersecurity expertise. Recommendations are expressed in operational language and supported by directly usable deliverables.

Which technical standard is associated with the Regulation?

The future European standard EN 50742, dedicated to protecting machinery against corruption, is currently under development to support the Machinery Regulation. IEC 62443 also provides a useful reference for structuring certain industrial cybersecurity measures, depending on the scope and machine architecture.

Contact

Let's talk

Are you preparing your machines for the requirements of EU Machinery Regulation 2023/1230, or looking to gain better control over the cyber risks affecting your OT environment?

An initial conversation helps clarify your situation, priorities and possible next steps โ€” with no commitment and no standardised sales pitch.

// Worth noting

Initial conversation with no commitment
Engagements across French-speaking and German-speaking Switzerland, and Eastern France
Support in English or French
Independent approach, with no solution resale
Regulatory reference: EU Regulation 2023/1230